Legal

Privacy Policy

What we collect, why we collect it, and the control you have over it. We keep it to the minimum.

Last updated:

Terms of Service
On this page
  1. Who we are
  2. What we collect
  3. Why we use it
  4. Who we share it with
  5. How long we keep it
  6. Cookies
  7. Security
  8. Your rights
  9. Children
  10. Changes to this policy
  11. Contact

Who we are

This Privacy Policy explains how the team behind Lynx (“we”, “us”) handles your personal data. It applies to the Lynx website, the Lynx UI, dashboard and support channels.

We built Lynx to collect as little as possible. This policy explains what that is, why we need it and the control you have over it.

What we collect

Information you give us

  • Email address. Used to sign you in to the dashboard and send you service messages.
  • Account password. Used to sign you in to Lynx. We store it only as a salted hash, never in plain text, and cannot read it back.
  • Support messages. What you send us on Discord, together with your Discord username.

Information created when you use Lynx

  • License details. Your license key and its activation date.
  • Hashed hardware ID. A one-way hash derived from your device’s hardware identifiers. We store the hash, not the identifiers themselves, and use it to bind your license to your device and in script requests, as described below.
  • IP address and security logs. Your IP address, timestamps, Lynx UI version and the result of license checks, used to prevent fraud, key sharing and abuse.
  • Approximate location. Each time your license is used, we record an approximate location (such as country, region and city) derived from your IP address. We do not use GPS or any precise location. It lets us spot a key being used from places far apart, a sign that it is being shared.
  • HWID reset log. When you reset your HWID, we log the time, the reason you give, and whether the new hardware ID differs from the previous one, together with the approximate locations your license is used from before and after the reset. We use this to detect and prevent key sharing.
  • Windows version. The version and build of Windows on your PC, used for compatibility and troubleshooting.
  • Crash reports. When Lynx crashes, a report with technical details of the crash and your system, used to find and fix bugs.

Script HTTP requests

Scripts you run in Lynx can make HTTP requests to servers of their choosing. Lynx adds your hashed hardware ID to every such request in a header, so the receiving server can see it. Those servers are run by third parties, not by us, and their own privacy practices apply.

What we do not collect

Keys are bought from third-party resellers, which handle your payment under their own privacy policies. We do not receive your payment details or order information: the only part of your purchase we see is the license key you activate. We do not use advertising or cross-site tracking, and we do not sell personal data.

Why we use it

We use personal data only for the purposes below, each with a legal basis under the GDPR.

Deliver your licenseContract
Activating your key on your device and verifying it when Lynx starts.
Prevent fraud and abuseLegitimate interests
Detecting key sharing, resale, keys from reversed or fraudulent purchases and attacks on our infrastructure, including reviewing HWID resets and the approximate locations a license is used from.
Fix crashes and bugsLegitimate interests
Using crash reports and your Windows version to find, reproduce and fix problems in Lynx.
SupportContract
Answering your questions and resolving license or HWID issues.
Service messagesContract
Important notices about your license, security or changes to our policies. Never marketing without your consent.

Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time. See Your rights.

Who we share it with

We share personal data only with service providers that help us run Lynx, under agreements that require them to protect it:

  • hosting and database providers, to run our servers and the licensing system;
  • email delivery providers, to send service messages;
  • Discord, when you contact us there;
  • the servers your scripts send HTTP requests to, which receive your hashed hardware ID in a header.

We may also disclose information when the law requires it, or when it is necessary to protect our rights, our users or the public, for example to respond to a valid legal request or to investigate fraud.

Some providers process data outside your country. When data leaves the European Economic Area, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

We never sell or rent personal data.

How long we keep it

Email and license details
For the life of your license, and up to 12 months after it ends.
Hashed hardware ID
For the life of your license. Replaced when you reset your HWID.
Hashed password
For the life of your account. Replaced when you change your password.
IP address and security logs
90 days, unless needed longer to investigate a specific case of abuse.
Approximate location
90 days, unless needed longer to investigate a specific case of abuse.
HWID reset log
For the life of your license, so repeated resets can be recognized.
Windows version
Kept indefinitely.
Crash reports
Deleted automatically after 6 months. We keep only the number of crashes.
Support conversations
12 months after the conversation ends.

When data is no longer needed, we delete it or anonymize it.

Cookies

We use only cookies that are strictly necessary for the website and dashboard to work, for example to keep you signed in and to protect forms against abuse. They are set by us, never used for advertising, and do not follow you across other sites.

Because these cookies are essential, they do not require consent. You can block them in your browser, but the dashboard will not work without them.

We do not use analytics, advertising or social media cookies. The website may keep small, non-identifying preferences in your browser’s local storage.

Security

Data is encrypted in transit with TLS. Passwords are salted and hashed, never stored in plain text. Hardware identifiers are hashed before they are stored, access to personal data is limited to the people who need it, and our systems are monitored for abuse.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.

Your rights

Depending on where you live, including under the EU and UK GDPR, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your data.
  • Restrict how we use your data.
  • Port your data, in a structured, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time, where we rely on it.

To make a request, contact us on Discord. We may ask you to confirm that you own the license key or email address involved. We respond within 30 days.

Deleting your data ends your license, because we cannot deliver or protect a license without it.

You also have the right to lodge a complaint with your local data protection authority.

Children

Lynx is not directed at children under 16, and we do not knowingly collect their personal data without the consent of a parent or guardian. If you believe a child has given us personal data, contact us on Discord and we will delete it.

Changes to this policy

We may update this Privacy Policy as Lynx evolves. We will post changes on this page and update the date at the top. For material changes, we will let you know on our Discord or by email before they take effect.

Contact

Questions or requests about your data? Reach us through Discord.